CVE-2023-41967CWE-1272

Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's…

Low · published December 18, 2023

CVSS v3.1
2.4
EPSS
0%
Percentile
23.5
In the wild
Unconfirmed
What it is

Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical access to the Controller to view its configuration through the diagnostic web pages.

This issue affects: Gallagher Controller 6000 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), v8.60 or earlier.

The record
Technical detail
CVSS v3.1
2.4 · LOW
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00311 · 23.5th percentile
Weakness
CWE-1272 · Sensitive Information Uncleared Before Debug/Power State Transition
Published
2023-12-18T22:00Z
EPSS history
Timeline
  • 18 DEC 22:00Z
    Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's…
    cvelistv5